The Canadian Centre for Cyber Security published four security advisories on 2026-07-10 covering critical vulnerabilities in Roundcube Webmail, Broadcom/VMware Tanzu products, Microsoft Edge, and Bitwarden Server. The most urgent advisory (AL25-007 Update 1) confirms ongoing exploitation of CVE-2024-42009 and CVE-2025-49113 in Roundcube Webmail, where attackers first obtain valid credentials via CVE-2024-42009 and then leverage CVE-2025-49113 (a Post-Auth RCE via PHP Object Deserialization) to achieve remote code execution. Both CVEs are listed in CISA's KEV catalog, and a proof-of-concept exists for CVE-2025-49113.
CVE-2025-49113
2 posts
Cyber Centre Daily Advisory Digest — 2026-07-10 (4 advisories) One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation UNK_MassTraction, a suspected China-aligned threat cluster, has been exploiting chained n-day vulnerabilities in Roundcube mailservers (CVE-2024-42009 XSS followed by CVE-2025-49113 PHP deserialization) targeting physics and engineering departments at US and Canadian universities since May 2026. The campaign deploys a custom JavaScript credential stealer (IceCube), a webshell (SquareShell), and the VShell backdoor via an in-memory ELF loader, treating mailservers as edge devices for network pivot. The tooling demonstrates mature operational security including anti-forensics, fallback mechanisms, and process spoofing.